-
Liang Yao commented on the post, Week 1 Questions, on the site 8 years, 2 months ago
Most of the companies have a “provisioning” process to grant, change and revoke user access. Howvere, as you described, the process could heavily rely on maual. In this case, what companies usually do to mitigate the risk?
-
Liang Yao commented on the post, Week 1 Questions, on the site 8 years, 2 months ago
Good summary, How about leave the laptop and other sensitive doc in the vehical?
-
Liang Yao commented on the post, Progress Report for Week Ending, February 9, on the site 8 years, 2 months ago
Please make a note and we should revisit this in a few weeks when discussing Windows audit. Ask yourself “so what”?
-
Liang Yao commented on the post, Progress Report for Week Ending, February 23, on the site 8 years, 2 months ago
You mentioned the Board. When dealing with cyber security risk, large organization’s board members should have someone with adequate background to understand the issue.
-
Liang Yao commented on the post, Week 1 Questions, on the site 8 years, 2 months ago
We will discuss Data Leakage Prevention (DLP) program during the class.
-
Liang Yao commented on the post, Week 1 Questions, on the site 8 years, 2 months ago
What you observed were the facts or symptoms of the issues. Ask yourself “so what” ? What’s the consequence?
-
Liang Yao posted a new activity comment 8 years, 2 months ago
It is auditors’ responsibility to make recommendations to management regarding audit findings. However, auditors should recommend “What” needs to be done not “How” actions should be developed and implemented. Said, please reminder me to elaborate this point next week.
-
Liang Yao commented on the post, Progress Report for Week Ending, February 9, on the site 8 years, 2 months ago
Please bring this point to the class next week. You are absolutely right. Auditors’ role is to “independently” assessing the controls implemented by management. Auditors should neither design nor deploy any controls.
-
Liang Yao commented on the post, Progress Report for Week Ending, February 16, on the site 8 years, 2 months ago
When we assessing IT risks across the enterprise, risks associated with different geographic locations could be very different and should be considered accordingly.
-
Liang Yao commented on the post, Progress Report for Week Ending, February 16, on the site 8 years, 2 months ago
Good point. We will discuss the skillsets required to be a qualified IT auditor.
-
Liang Yao commented on the post, Happy Birthday SNL // the typists from the Carol Burnett show, on the site 8 years, 2 months ago
yes…we will discuss data leakage prevention (DLP) program in information security session. During that session, we will talk about risk associated with removable drivers and controls should be in place to mitigate such risk.
-
Liang Yao commented on the post, Happy Birthday SNL // the typists from the Carol Burnett show, on the site 8 years, 2 months ago
we will drill down IT risk categories soon…:)
-
Liang Yao commented on the post, Happy Birthday SNL // the typists from the Carol Burnett show, on the site 8 years, 2 months ago
How about financial auditors or operation auditors? Why it’s important for them to have some understanding of technology?
-
Liang Yao wrote a new post on the site ITACS 5205 8 years, 4 months ago
Fall 2017 Class Schedule:
Every Tuesday starting August 29th, 2017
5:30 pm – 8:00 pm
Class Location: Alter Hall 0A602 & Online via WeBex
All IT Auditor Candidates – Welcome to MIS5205!
MIS 5205, […]
-
Liang Yao wrote a new post on the site ITACS 5205 8 years, 4 months ago
Fall 2016 Class Schedule:
Every Wednesday starting August 31st, 2016
Learnerthone (5 sessions) 5:30 pm – 8:00 pm
Meetups ( 10 sessions) 5:30 pm – 7:00 pm
Meeting Location: Online via WeB […]
-
Liang Yao wrote a new post on the site MIS5205.001 9 years, 2 months ago
Fall 2015 Class Schedule: Every Monday, 5:30 pm – 8:00 pm
Meeting Location: Speakerman Hall 113
All IT Auditor Candidates – Welcome to MIS5205!
IT Service Delivery and Support is to teach students to […]
-
Liang Yao wrote a new post on the site IT Service Delivery and Support 10 years, 10 months ago